CVE Published: 12/11/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: microsoft |
Vendor: Microsoft |
Product: Microsoft Office Status : PUBLISHED
CVE-2019-1449 Description
A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka \'Microsoft Office ClickToRun Security Feature Bypass Vulnerability\'.